Junglewise Threat Intelligence

CVE-2014-9755: Viprinet Multichannel VPN Router 300 protocol downgrade and replay attack

CVE-2014-9755 · Severity: high · CVSS 7.5 · Published 2017-01-20

Executive brief

The Viprinet Multichannel VPN Router 300 contains a security flaw where the hardware VPN client fails to verify the identity of the server it is connecting to. This allows a remote attacker to intercept or manipulate VPN traffic by impersonating a legitimate VPN endpoint. Such an attack could lead to unauthorized access to network traffic or a disruption of secure communications.

Technical details

The hardware VPN client in Viprinet Multichannel VPN Router 300 (versions 2013070830 and 2013080900) does not validate the remote VPN endpoint's identity by checking its SSL key during the TLSv1.1 handshake. This lack of certificate validation allows a remote attacker to perform a Man-in-the-Middle (MitM) attack. Specifically, the vulnerability facilitates a protocol downgrade attack where an attacker can force the client to use version 2 of the protocol instead of version 3. This flaw can be exploited to perform replay attacks or intercept sensitive data within the VPN tunnel. The issue is addressed in firmware versions 2014013131 and 2014020702.

Affected products

  • Viprinet Multichannel VPN Router 300 firmware 2013070830, 2013080900

Timeline

  • 2016-02-03: disclosed: Public disclosure via Full Disclosure mailing list
  • 2017-01-20: advisory: NVD published date

References

Related threats